{"id":"CVE-2024-45600","summary":"Fields GLPI plugin has an Authenticated SQL Injection","details":"Fields is a GLPI plugin that allows users to add custom fields on GLPI items forms. Prior to 1.21.13, an authenticated user can perform a SQL injection when the plugin is active. The vulnerability is fixed in 1.21.13.","aliases":["GHSA-wwxw-64g6-2992"],"modified":"2026-08-12T03:51:27.776759098Z","published":"2024-12-26T21:27:01.168Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/45xxx/CVE-2024-45600.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-89"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/45xxx/CVE-2024-45600.json"},{"type":"ADVISORY","url":"https://github.com/pluginsGLPI/fields/security/advisories/GHSA-wwxw-64g6-2992"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-45600"},{"type":"FIX","url":"https://github.com/pluginsGLPI/fields/commit/eb927b0f084ee4ef6c87ab2eb7a15e99369e74ae#diff-a7024a397fba9a026157683da73cc675ec6b73bd900374b3836bcdc76ec7bd5cR1166"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pluginsglpi/fields","events":[{"introduced":"0"},{"fixed":"eb927b0f084ee4ef6c87ab2eb7a15e99369e74ae"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.21.13"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["1.21.12","1.21.11","1.21.10","1.21.9","1.21.8","1.21.7","1.21.6","1.21.5","1.21.4","1.21.3","1.21.2","1.21.1","1.21.0","1.20.7","1.20.6","1.20.5","1.20.4","1.20.3","1.13.0","1.20.2","1.20.1","1.20.0","1.19.0","1.18.2","1.18.1","1.18.0","1.17.3","1.17.2","1.17.1","1.17.0","1.16.0","1.15.3","1.15.2","1.15.1","1.15.0","1.14.0","1.12.12","1.12.11","1.12.9","1.12.8","1.12.7","1.12.6","1.12.5","1.12.4","1.12.3","1.12.2","1.12.1","1.12.0","1.11.0","1.10.3","1.10.2","1.10.1","1.10.0","1.9.2","1.9.1","1.9.0","1.8.2","1.8.1","1.8.0","1.7.3","1.7.2","1.7.1","1.7.0","1.6.2","1.6.0","0.90-1.3","0.90-1.2","0.90-1.1","0.90-1.0","0.85-beta-6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-45600.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"}]}